How can my server for a Connect add-on determine what permissions a user has? I'm looking for ADMINISTER specifically, but it's unlikely to be right-specific.
I found two options, none of which seems ideal:
- /rest/api/2/user/permission/search - according to docs it requires "admin" to access, which is way too strong a scope to ask for an add-on that claims to never ever even write to JIRA.
- /rest/api/2/mypermissions - requires ACT_AS_USER, which seems pretty strong as well (permission to perform any action on behalf of any user? ouch!).
Am I missing something? Are these the only options?